Backdoored PyTorch Lightning package drops credential stealer

2026-05-04T19:23:36Z763923704c7244bcab31c4148273f7903f0e64124e2d3ec81f420f256d61c901
PyPIandroid-malwareauth-bypassbackup-failureconsentfixcopy-failcpanelcredential-stealerdata-breachdigicertfalse-positiveinstructurelinuxmicrosoftmoveitoauth-abusepytorch-lightningransomwareroot-exploitshinyhunterssource-code-leaksupply-chaintelegram

What happened

Multiple active threats and incidents reported: a backdoored PyTorch Lightning PyPI package was distributing a credential‑stealer targeting browsers, environment files and cloud credentials; Progress warned of a critical authentication‑bypass flaw in MOVEit Automation with urgent patching advised; the "Copy Fail" Linux vulnerability is being exploited in the wild to gain root; cPanel flaw CVE-2026-41940 is being mass‑exploited in "Sorry" ransomware attacks. Additional notable items include source‑code/data breaches at Trellix and Instructure (ShinyHunters claim), Microsoft April updates that破破

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
763923704c7244bcab31c4148273f7903f0e64124e2d3ec81f420f256d61c901
Enrichment time
2026-05-04T19:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.